astral-tokio-tar is vulnerable to UNIX Symbolic Link (Symlink) Following
30
Low Risk
In affected versions of this package, the unpack_in API could inadvertently modify the permissions of external (i.e. non-archive) directories outside of the archive. An attacker could use this to contrite a tar archive that maliciously changes directory permissions outside of its intended hierarchy. This flaw only affects directories; individual file permissions cannot be modified via it.
You are affected if you are using a version that falls within the vulnerable range.
astral-tokio-tar is vulnerable to UNIX Symbolic Link (Symlink) Following in versions 0.0.1 - 0.6.0.
Upgrade the astral-tokio-tar library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant